ISO 22301 Guide: Business Continuity Management, Certification & Cost

Shubham S.
August 23, 2026
24
mins

A customer's security team asks for evidence of your business continuity program. You've got a SOC 2 report, an ISO 27001 certificate, maybe both. Neither one is what they're actually asking about.

ISO 22301 is the international standard for a Business Continuity Management System (BCMS). It sets out how an organization plans for, responds to, and recovers from disruptions, from a cloud outage to a supplier failure to a natural disaster. Certification against it proves that system actually works, not that a plan exists somewhere in a shared drive nobody's opened since the last audit.

Quick answer ISO 22301 certifies a Business Continuity Management System (BCMS) built around 10 clauses: a documented context and leadership commitment, a planning process built on business impact analysis, and an operational core that includes continuity strategies, tested plans, and an ongoing exercise program. It shares its high-level structure with ISO 27001, which makes it meaningfully easier to pursue for a company that already holds one.

This guide covers what ISO 22301 actually requires, what a BCMS is in practice, how RTO and RPO work with a real worked example, what certification costs (a question no certification body or guide answers honestly), and how it connects to the frameworks you may already have in place.

Here's what's ahead:

  • What ISO 22301 is, and what a BCMS actually is
  • Why business continuity management matters even for a small, resource-constrained team
  • What changed between the 2012 and 2019 editions
  • How ISO 22301 relates to ISO 27001 and SOC 2
  • The 10 clauses, explained in plain language, plus a quick ISO 22301 checklist
  • RTO vs. RPO, with a concrete worked example
  • How certification actually works, and how long it takes
  • What certification costs, named honestly
  • Common mistakes companies make pursuing it

What Is ISO 22301?

ISO 22301 is the standard that specifies requirements for a Business Continuity Management System, or BCMS. A BCMS is a structured, auditable way of preparing for disruptive incidents and keeping critical operations running, or recovering them quickly, when something breaks.

ISO 22301 doesn't hand a company its continuity plan. It certifies that the system behind that plan, the way it's built, tested, and kept current, meets an internationally recognized bar. That distinction matters more than it sounds like it should: a plan can look complete on paper and still fail the first time it's actually needed, because nobody built a system to maintain or test it.

Quick take ISO 22301 certifies the system behind the plan, not the plan document itself.

This is a different thing from a generic business continuity and disaster recovery (BCDR) plan. If what you actually need right now is help writing that plan, ComplyJet's guide to building a business continuity and disaster recovery plan covers what to put in one across SOC 2, ISO 27001, HIPAA, GDPR, and PCI DSS. This article is about the ISO standard that governs the management system behind that plan, not the plan document itself.

The disruptions a BCMS is built to handle aren't exotic. A cloud region goes down for six hours. A key payment processor has an outage during a busy sales period. A ransomware incident takes core systems offline for days, not hours. A single-source supplier fails without warning. ISO 22301 doesn't care which of these actually happens; it cares whether the organization had a system in place to keep operating, or recover quickly, regardless of which one did.

Different trigger, same system, same response process:

Four different disruption types, a cloud outage, a payment processor outage, a ransomware incident, and a supplier failure, all feeding into one Business Continuity Management System that responds the same way regardless of which one happens.

Who it applies to: ISO 22301 is written to apply to organizations of any size and sector. In practice, nearly every guide on this topic writes exclusively for large enterprises with dedicated resilience teams. A lean version of this system is realistic for a 30-person startup too, and the next section gets specific about what that actually looks like.

What Is a BCMS? ISO 22301 BCMS Explained

BCMS stands for Business Continuity Management System. It's not a single document. It's the ongoing set of policies, processes, and capabilities that let an organization identify threats to its operations, decide how much disruption it can actually tolerate, and respond when something breaks.

A BCMS runs on the same Plan-Do-Check-Act logic as an ISO 27001 Information Security Management System (ISMS): build the system, run it, check whether it's working, and improve it based on what you find. That shared logic is the reason the two standards pair so naturally, covered in full a few sections down.

Quick take A BCMS is a system, not a document. If the only artifact you can point to is a PDF, there's no BCMS yet, just a plan that hasn't been tested.

Why ISO 22301 Business Continuity Management Matters for Startups and SaaS Companies

ISO 22301 business continuity management matters well before a company is large enough to have a dedicated resilience team. The stakes here are concrete, not abstract risk-management language. Enterprise customers increasingly ask for evidence of business continuity capability alongside, or sometimes instead of, a SOC 2 report, especially once a vendor becomes operationally critical to their own business.

A vendor security review that used to stop at "do you have backups" now regularly asks how fast you can recover a specific system, what your tested recovery time actually is, and who owns the plan when something goes wrong at 2 a.m. Those are BCMS questions, not general security questions, and a company without a real answer loses credibility in that review regardless of how strong its security posture otherwise is.

Note Scoping a BCMS realistically starts small. Start with the systems and processes that would actually stop revenue or violate a contract if they went down, not a company-wide inventory of every process that exists.

That scoping discipline is what makes ISO 22301 workable for a 30-person company instead of something that only makes sense once you have a dedicated resilience team. Scope it to what actually matters operationally, prove that scope works, and expand it as the business grows.

Picture a 40-person SaaS company whose core product depends on a single managed database provider. That provider has a multi-hour outage during a customer's peak usage window.

Without a BCMS, the response is improvised: someone finds out from a customer complaint, nobody's sure who's authorized to fail over to a backup region, and the postmortem turns up a recovery plan that was written 18 months ago and never tested.

With even a lean BCMS scoped to that one dependency, the same outage triggers a rehearsed runbook, a known decision-maker, and a recovery time the team has actually verified is achievable. That gap, rehearsed versus improvised, is what certification is actually checking for.

Bottom line Rehearsed beats improvised. That's the entire gap ISO 22301 certification is designed to close, at any company size.

ISO 22301:2019 vs. ISO 22301:2012: What Actually Changed

ISO 22301:2012 was the original edition, and it holds a specific distinction: it was the first ISO management-system standard to fully adopt the Annex SL high-level structure, the same shared skeleton ISO later rolled out across ISO 27001, ISO 9001, and other management-system standards.

ISO 22301:2019 is the current, second edition, published October 31, 2019. It refactored the standard to remove redundant language and tighten the wording, without changing the underlying requirements in any substantive way. If you're certifying today, you're certifying against the 2019 edition. The 10-clause structure covered later in this guide is the 2019 structure.

Laid out on a timeline:

ISO 22301 version timeline: 2012, the original edition and the first ISO management-system standard to adopt the Annex SL structure; 2019, the current edition, refactored for clarity with the same requirements; ongoing, revision work in progress at ISO but not yet published.

The standard is due for further work. ISO's technical committee has ongoing revision activity in progress, including sustainability-related additions, but as of this writing, ISO 22301:2019 remains the current, enforceable edition organizations are actually certified against. Treat any claim about a newer numbered edition with some caution until it's confirmed directly against ISO's own published standard.

Why the version matters practically: auditors certify against the current edition specifically, so pre-2019 material still circulating online, including some of the standards body's own older reference material, may already be out of date on structure or clause numbering.

How the ISO 22301 Standard Relates to ISO 27001 and SOC 2

ISO 22301 shares the Annex SL high-level structure with ISO 27001. Same clause-numbering logic, context, leadership, planning, support, operation, performance evaluation, improvement, mapped onto continuity management instead of information security.

That shared skeleton has a real practical payoff. A company already certified to ISO 27001 has already built most of the management-system muscle ISO 22301 also requires: a documented scope, management review, an internal audit process, a corrective-action mechanism. The incremental work to add ISO 22301 is continuity-specific, a business impact analysis, recovery strategies, an exercise program, not building a management system from zero.

One shared Annex SL skeleton branching into three ISO management-system standards: ISO 27001 for information security, ISO 22301 for business continuity, and ISO 9001 for quality, each adding its own topic-specific requirements on top of the same base structure.
Framework What it certifies How it relates to ISO 22301
ISO 27001 An Information Security Management System (ISMS) Shares Annex SL structure with ISO 22301, making a combined implementation genuinely lighter than building each separately
SOC 2 Controls against the Trust Services Criteria, reported by an auditor for a defined period The Availability criterion touches similar ground but isn't equivalent; SOC 2 is a point-in-time/period report, ISO 22301 certifies an ongoing management system

Adopting the ISO 22301 standard on top of an existing ISO 27001 program means the scope, management review cadence, and internal audit process can often be shared rather than duplicated, which is the single biggest practical reason the two are usually pursued together rather than independently.

SOC 2 companies should note the distinction carefully. SOC 2's Availability criterion asks whether your systems are available as committed, and touches concepts like backup and disaster recovery. It does not require or replace the structured BCMS, clause-by-clause, that ISO 22301 certifies. The two are complementary, not interchangeable, and a customer asking specifically about ISO 22301 won't be satisfied by a SOC 2 report alone.

The mistake I see most often isn't misunderstanding what ISO 22301 requires. It's assuming a SOC 2 report or an ISO 27001 certificate already covers business continuity, and finding that out isn't true during a customer's actual due diligence review. — Upendra Varma, CTO at ComplyJet

ISO 22301 Requirements: The 10 Clauses Explained

The ISO 22301 requirements break down into 10 clauses. The first three are front matter, scope, normative references, and terms and definitions, and don't carry auditable requirements on their own. Clauses 4 through 10 are the mandatory, auditable core.

Clause What it actually requires
1. Scope Defines what the standard covers; no organization-specific requirement
2. Normative references Points to related standards used for terms and definitions; no organization-specific requirement
3. Terms and definitions Shared vocabulary for the standard; no organization-specific requirement
4. Context of the organization Understand the organization, its interested parties, and the scope of the BCMS
5. Leadership Top management commits to the BCMS, sets policy, and assigns roles and authorities
6. Planning Address risks and opportunities, set business continuity objectives, and plan to achieve them
7. Support Provide the resources, competence, awareness, communication, and documented information the BCMS needs
8. Operation Run the operational core: business impact analysis, risk assessment, continuity strategies, plans, and exercising
9. Performance evaluation Monitor, measure, internally audit, and formally review the BCMS
10. Improvement Correct nonconformities and drive continual improvement based on what performance evaluation finds

Clause 8 (Operation) is where the real work lives. It breaks down into six practical pieces:

  • Operations planning and control: the day-to-day discipline of running the BCMS as designed, not just having designed it
  • Business impact analysis (BIA) and risk assessment: identifying which activities matter most, what depends on them, and what threatens them, the analysis that everything else in this clause is built on
  • Business continuity strategies and solutions: deciding how the organization will actually respond to and recover from the disruptions the BIA identified
  • Business continuity plans and procedures: the documented, actionable version of those strategies, specific enough for someone to actually follow under pressure
  • Exercise program: testing the plans on a real schedule, tabletop exercises, simulations, or full-scale tests, not writing them once and hoping
  • Evaluation of business continuity documentation and capabilities: checking, after exercising, whether the plans and capabilities actually held up

ISO 22301 Checklist: A Quick-Reference Summary

A condensed version of the table above, phrased as actions:

  • Define your organization's context, interested parties, and BCMS scope
  • Get documented top-management commitment and a business continuity policy
  • Run a business impact analysis and risk assessment
  • Set concrete business continuity objectives, including RTO and RPO targets
  • Build continuity strategies and documented plans for your highest-impact scenarios
  • Provide the resources, training, and awareness the plans depend on
  • Exercise the plans on a real schedule, not just once before an audit
  • Monitor performance, run internal audits, and correct what they find

RTO vs. RPO Under ISO 22301: A Plain-Language Example

This is where nearly every existing guide on ISO 22301 goes quiet, and it shouldn't. RTO and RPO are the two numbers a BCMS actually lives or dies by, and they deserve a real definition, not a mention in passing.

Recovery Time Objective (RTO) is the maximum acceptable time a system or process can be down before the disruption becomes unacceptable to the business.

Recovery Point Objective (RPO) is the maximum acceptable amount of data loss, measured as a length of time, between the last good state before a failure and the point of failure itself.

Put plainly: RTO is about how long you can be down. RPO is about how much you can afford to lose.

Timeline showing RPO as the window looking backward from a failure point to the last good backup, measuring acceptable data loss, and RTO as the window looking forward from failure to recovery, measuring acceptable downtime.

Here's what that looks like with real numbers attached:

Worked example A SaaS company's payments-processing system goes down. Its business impact analysis set an RTO of 4 hours and an RPO of 15 minutes for this system.

The 4-hour RTO means the team has 4 hours to restore payment processing before the disruption crosses from "manageable" to "unacceptable," triggering a specific failover runbook, not an ad hoc scramble. The 15-minute RPO means backups or replication have to run frequently enough that, worst case, only 15 minutes of transaction data is ever at risk.

Neither number is arbitrary. Both come out of the business impact analysis, weighed against what customers, contracts, and revenue can actually absorb.

That last point matters more than the definitions themselves. RTO and RPO targets are an output of the business impact analysis covered in Clause 8.2 above, not numbers picked because they sound aggressive enough to put in a sales deck. A 15-minute RPO commits real infrastructure and cost (frequent backups, replication, monitoring); setting one without checking whether it's actually achievable is a common and expensive mistake, covered further in the mistakes section below.

How ISO 22301 Certification Actually Works

Quick answer Readiness assessment, build the BCMS, internal audit, external Stage 1 and Stage 2 audits, certification, then annual surveillance audits until the three-year recertification cycle.

The certification path follows the same general shape as ISO 27001's: a readiness or gap assessment against the 10 clauses, BCMS implementation (policies, the business impact analysis, continuity strategies, documented plans), an internal audit, an external Stage 1 audit (documentation review) and Stage 2 audit (operational verification that the BCMS is actually running as designed), then certification, followed by ongoing surveillance audits and periodic recertification.

This is overview depth on purpose. Every organization's starting point is different, and a genuinely useful step-by-step walkthrough depends on specifics (existing management systems, team size, current documentation) this guide isn't scoped to assume.

The same path, laid out as a sequence:

ISO 22301 certification path as a seven-step sequence: readiness assessment, build the BCMS, internal audit, Stage 1 audit, Stage 2 audit, certified, then annual surveillance audits looping back until the three-year recertification cycle.

Stage 1 and Stage 2 follow the same pattern most ISO management-system audits use. Stage 1 is a documentation review: the auditor checks that the BCMS's policy, scope, business impact analysis, and plans actually exist and cover what they need to.

Stage 2 is operational verification, further out on the calendar. The auditor checks that the BCMS is genuinely running as documented, not just written down, which typically means reviewing exercise records, internal audit results, and management review minutes rather than just re-reading the same policy documents.

Quick recap Stage 1 checks whether the paperwork exists. Stage 2 checks whether the organization actually follows it.

There's a real advantage for a company already running an ISO 27001 ISMS, covered in the standards-relationship section above: the same certification-body relationship, internal audit process, and management review cadence can often extend to cover both systems, rather than running two unrelated certification tracks with two separate audit calendars.

Certification itself isn't a one-time event. Like other ISO management-system certifications, it typically runs on a three-year cycle, with annual surveillance audits in between to confirm the BCMS is still operating as certified, and a full recertification audit at the end of the cycle. A company that treats certification as a finish line rather than the start of an ongoing audit relationship tends to find that out the hard way at the first surveillance visit.

How Long Certification Actually Takes

Starting point Realistic timeline
No existing management system Around a year, sometimes longer, depending on team size and how much of the BCMS has to be built from scratch
Already running an ISO 27001 ISMS Several months, since scope, management review, and internal audit processes can extend rather than start over

That range depends heavily on how ready the organization is going in, not a fixed timeline any credible source can promise upfront.

What Does ISO 22301 Certification Cost?

Here's the honest answer: no certification body, audit firm, or training provider publishes a real ISO 22301 certification cost figure, range, or even a breakdown of the factors that drive it. That's a genuine blank spot, and it exists despite real search demand from people trying to actually budget for this.

Myth debunking "There's a standard ISO 22301 certification cost you can look up." No. Certification bodies price this individually based on scope and audit days, and none publish a rate card. Anyone quoting a specific number without knowing your organization's size and scope is estimating, not quoting.

What genuinely drives cost: organization size and the scope of what the BCMS covers, whether the BCMS is built from scratch or extends an existing ISO 27001 ISMS, certification-body audit fees versus the internal implementation effort (staff time, consultant support if used), and whether a compliance-automation platform handles evidence and documentation versus a fully manual or consultant-led process.

If you're budgeting for this, ask any certification body you're evaluating for a scoped quote based on your organization's actual size and BCMS boundary. A published rate card doesn't exist publicly for this standard.

Common Mistakes Companies Make With ISO 22301

  • Treating the BCMS as a document exercise. A binder of plans nobody's tested isn't a management system, it's paperwork waiting to fail during the one incident that actually needed it. Auditors increasingly ask to see exercise records specifically because plans-only submissions are common enough to be an expected red flag.
  • Skipping the business impact analysis and picking RTO/RPO targets arbitrarily. A 15-minute RPO sounds impressive in a sales conversation and becomes an expensive, unmet promise if nobody checked whether the backup and replication infrastructure behind it can actually hit that number under real load.
  • Never running a real exercise before the audit. Tabletop exercises and simulations exist to find the gaps in a plan before a real incident does, not to check a box. A plan that's never been walked through out loud with the people who'd actually execute it usually has gaps nobody's noticed yet.
  • Scoping the BCMS too broadly for the team to realistically maintain. A 30-person company doesn't need every process in the company covered on day one; scope to what would actually stop revenue or violate a contract, then expand as the business and the team grow into it.
  • Building the BCMS in isolation from an existing ISO 27001 ISMS. Duplicating management-review meetings, internal audit processes, and documentation structures that could be shared wastes real time and money, and makes maintaining both systems long-term noticeably harder than it needs to be.
  • Assuming certification alone satisfies a specific customer's continuity requirements. Check what the customer actually asked for. A certificate doesn't automatically answer a specific RTO/RPO question in a vendor questionnaire, and a mismatch here can stall a deal just as effectively as having no certification at all.
  • Letting the BCMS go stale after certification. Clauses 9 and 10, performance evaluation and improvement, are ongoing work, not a one-time step you finish and file away. A BCMS that hasn't been reviewed since the certification audit is exactly the kind of gap a surveillance audit is designed to catch.

Laid out as a quick-reference grid:

Grid of seven common ISO 22301 mistakes: treating the BCMS as a document exercise, picking RTO and RPO targets arbitrarily, never running a real exercise, scoping too broadly, building in isolation from ISO 27001, assuming certification alone satisfies a customer, and letting the BCMS go stale after certification.

Where ISO 22301 Fits Into a SOC 2 or ISO 27001 Program

ComplyJet doesn't currently support ISO 22301 as a certifiable framework, so this isn't a pitch to get certified against it here. Worth saying plainly rather than implying otherwise.

What is genuinely true: business continuity and disaster recovery planning is already a documented requirement inside the SOC 2 and ISO 27001 programs ComplyJet does support, the Availability criteria under SOC 2, and Annex A controls 5.29 and 5.30 under ISO 27001. If you're building toward ISO 22301, the continuity work you're doing (business impact analysis, recovery strategies, tested plans) overlaps directly with what those audits already expect from you.

Business Continuity
Already building this work for SOC 2 or ISO 27001?
ComplyJet helps companies build and evidence the business continuity and disaster recovery work their SOC 2 and ISO 27001 programs already require. See our full guide to building a business continuity and disaster recovery plan across every framework we support.
Read the BCDR guide

FAQs

What Is ISO 22301, in Plain English?

ISO 22301 is the international standard for a Business Continuity Management System, or BCMS. It sets out how an organization should plan for, respond to, and recover from disruptions, and certification proves that the system behind those plans actually works.

What Does ISO 22301 Certification Involve?

A readiness or gap assessment against the standard's 10 clauses, building or extending the BCMS itself, an internal audit, then an external Stage 1 and Stage 2 audit from a certification body, followed by ongoing surveillance audits. See the certification section above for the full walkthrough.

How Much Should You Budget for ISO 22301 Certification?

There's no published rate card. Certification bodies price this based on your organization's size and BCMS scope, and cost is genuinely undocumented industry-wide. Ask any certification body you're evaluating for a scoped quote rather than trusting a generic figure.

What Are the Core ISO 22301 Requirements?

Ten clauses, with clauses 4 through 10 carrying the mandatory, auditable requirements: context, leadership, planning, support, operation (the business impact analysis, strategies, plans, and exercising), performance evaluation, and improvement. The full table is above.

What Does BCMS Stand For?

Business Continuity Management System. An ISO 22301 BCMS is the ongoing system the standard certifies, built from policies, processes, and tested capabilities, not a single plan document.

Do You Need ISO 27001 Before Pursuing ISO 22301?

No. The two standards have no formal prerequisite relationship. They do share the Annex SL high-level structure, so a company already certified to ISO 27001 typically finds the incremental lift to ISO 22301 smaller than building a management system from zero.

What's the Real Difference Between RTO and RPO?

RTO (Recovery Time Objective) is how long a system can stay down before it's unacceptable. RPO (Recovery Point Objective) is how much data loss, measured in time, is acceptable. These ISO 22301 RTO RPO definitions both come out of a business impact analysis, not a number chosen in isolation.

Is Certification Legally Mandatory?

No. ISO 22301 certification isn't a legal or regulatory requirement in most jurisdictions or industries. It's increasingly expected contractually by enterprise customers, and treated as evidence of operational resilience in some regulated sectors, but nothing forces certification by law.

What Actually Changed From ISO 22301:2012 to ISO 22301:2019?

The 2019 edition refactored the standard's wording to remove redundancy and improve clarity, without changing the underlying requirements in any substantive way. If you're certifying today, you're certifying against the 2019 edition.

Related Reading

Sources: ISO 22301 (Wikipedia), version history and clause structure; certification-process and clause-depth detail cross-checked against ISMS.online's ISO 22301 overview and Schellman's ISO 22301 requirements breakdown.